Live data from Hacker News

Targeted attack on our management with the Triangulation Trojan

usa.kaspersky.com

31–40 of 131 posts

Re: Targeted attack on our management with the Triangulation Trojan

#31

tl;dr - malicious state and private threat actors can at any time completely take over your iphone (root access) with an invisible iMessage without you having a practical chance to detect it besides scanning your iphone backup

It still blows my mind that this is not a known fact by most people for as long as phones have existed? Or maybe it is?

Re: Targeted attack on our management with the Triangulation Trojan

#32
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

Apple's marketing might have a different stance but engineers on their security team don't really consider these to be security features.

Re: Targeted attack on our management with the Triangulation Trojan

#33
post #24

Adjacent topic but i have a friend who told me buying a refurbished iPhone from a local shop was a bad idea from a security perspective. Is this true? I thought a hard reset and secure enclave etc. was enough? Can you put "stuff" in it that survives to a new user?

Exploits that survive a full wipe are almost unheard of on iOS.

Re: Targeted attack on our management with the Triangulation Trojan

#34

tl;dr - malicious state and private threat actors can at any time completely take over your iphone (root access) with an invisible iMessage without you having a practical chance to detect it besides scanning your iphone backup

Should add that this can only occur if you haven't updated your phone in over a year.

Re: Targeted attack on our management with the Triangulation Trojan

#35
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

And it's not RMS who said it :-)

Re: Targeted attack on our management with the Triangulation Trojan

#36
post #23
post #22

Earlier quoted context omitted.

Does an OS upgrade remove this malware though? Maybe it doesn't and it's why so many phones were infected.

The article says: >An indirect indication of the presence of Triangulation on the device is the disabling of the ability to update iOS. So I assume that the malware stops working when iOS is updated. This highlights the tremendous importance of keeping software up to date.

[deleted]

Re: Targeted attack on our management with the Triangulation Trojan

#37
post #17
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Why are they using iOS if they feel that way about it? Also: iOS 16 is not vulnerable and it was released on September 12, 2022 - why are those phones out of date for so long?

That one of the bigger security companies seemingly didn't have MDM screaming bloody murder or outright blocking authentication for an endpoint this out of date is more than a little concerning.

Props to their SIEM for detecting it in the end, but this seems like it could've been detected and remediated a few weeks in (assuming it didn't also have the ability to spoof the iOS version).

Re: Targeted attack on our management with the Triangulation Trojan

#38
post #23
post #22

Earlier quoted context omitted.

Does an OS upgrade remove this malware though? Maybe it doesn't and it's why so many phones were infected.

The article says: >An indirect indication of the presence of Triangulation on the device is the disabling of the ability to update iOS. So I assume that the malware stops working when iOS is updated. This highlights the tremendous importance of keeping software up to date.

> the disabling of the ability to update iOS.

This is done by the malware.

Indeed, the identified fix involves a factory reset and upgrading iOS to prevent the malware from taking over again.

That provides a simple explanation for why the phones are running such an old version: because they've been infected and unable to be updated for that entire time.

Re: Targeted attack on our management with the Triangulation Trojan

#39
post #38
post #23

Earlier quoted context omitted.

The article says: >An indirect indication of the presence of Triangulation on the device is the disabling of the ability to update iOS. So I assume that the malware stops working when iOS is updated. This highlights the tremendous importance of keeping software up to date.

> the disabling of the ability to update iOS. This is done by the malware. Indeed, the identified fix involves a factory reset and upgrading iOS to prevent the malware from taking over again. That provides a simple explanation for why the phones are running such an old version: because they've been infected and unable to be updated for that entire time.

I guess execs at security firms are no better than average people when it comes to noticing that their phones never got the various new features (end emojis!) from the last year of OS updates.

Re: Targeted attack on our management with the Triangulation Trojan

#40
post #8

Kaspersky was spying on international citizens for over a decade, providing data for both the FSB and GRU. ...and now they're complaining about counter surveillance by the FBI?

How is disclosing an Apple security issue "complaining"?

It’s the polemics. Complaining is a matter of presentation, not content.

Plenty of security disclosures are matter of fact and not loaded with opinion and innuendo.

Post reply on HN